Threat Research | Weekly Recap [07 Jun 2026]

Threat Research | Weekly Recap [07 Jun 2026]
Cybersecurity Threat Research β€˜Weekly’ Recap. This week covered multiple supply-chain intrusions and downstream impacts, including PyPI and npm compromises, along with continued targeting of GitHub Actions and cloud/dev tooling for credential theft and CI/CD propagation. Activity also ranged from extortion and ransomware tradecraft to public-facing exploitation, phishing-led loader/RAT campaigns, cross-platform botnets, and agentic container/Kubernetes abuse, alongside guidance on improving backup recovery readiness and testing.

#Shai-Hulud #Miasma #Bun #RedHatCloudServices #MiniShai-Hulud #FamousChollima #UNC3753 #LunaMoth #Vect #TheGentlemen #Aspose #VerdantBamboo #UNC5221 #BRICKSTORM #AGENTPSD #PLENET #CVE-2026-0257 #YellowKey #GreenPlasma #MiniPlasma #ClickFix #CastleLoader #PureLogs #JS.MonoGlyphRAT #Havoc #NF-e #TaxShadow #XENOFISCAL #XenoRAT #C0XMO #Gafgyt #Gamaredon #GammaLoad #GammaSteel #GammaPhish #GammaWorm #OperationFlutterBridge #FlutterShell #BlueWallet #Argamal #TA4922 #BlindEagle #Handala #BRICKSTORM

Supply Chain Compromises

Ransomware, Extortion, and Data Theft

  • UNC3753 / Luna Moth ran vishing-led extortion against U.S. legal and financial firms using RMM tools and data leak pressure β€” Seeking Counsel
  • Vect ransomware emerged with affiliate recruitment, broad cross-platform reach, and wiper-like destructive behavior β€” Dark Web Profile: Vect Ransomware
  • The Gentlemen ransomware tradecraft centered on double extortion, GPO abuse, and encrypted exfiltration β€” Emulating the Gentlemen Ransomware
  • An espionage campaign quietly exfiltrated a stock exchange executive’s Outlook mailbox over months using cloud storage and an Aspose-based stealer β€” Stock Exchange Executive for Five Months

Cloud, Identity, and Supply-Chain Intrusions

Exploitation of Public-Facing Systems

Phishing, Loader, and RAT Campaigns

Botnets, Worms, and Cross-Platform Malware

  • C0XMO, a modular Gafgyt variant, spread across routers, Linux, and IoT with DDoS and exploitation features β€” Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO
  • Gamaredon continued its multi-stage GammaLoad, GammaSteel, GammaPhish, and GammaWorm chains against Ukraine β€” GammaPhish and GammaWorm
  • Follow-on analysis detailed GammaLoad persistence, registry-cached C2, and abuse of Telegram and Cloudflare infrastructure β€” GammaLoad
  • GammaSteel added fileless PowerShell theft, USB propagation, and dead-drop recovery for covert exfiltration β€” GammaSteel
  • Gamaredon and Turla showed operational overlap in a 2025 espionage alliance targeting Ukraine β€” Gamaredon x Turla

Malvertising, Mac, and Consumer Malware

Regional, Sector, and Actor Activity

Defensive Readiness and Recovery

  • Backup jobs can appear green while still failing recovery windows, making restore testing and latency governance critical β€” Backup operations at scale

Threat Research | Weekly Recap – hendryadrian.com